work-mvp

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches a dev-workflow orchestration skill, and there is no clear credential harvesting or exfiltration. However, the skill’s core behavior depends on an unverified `lev` binary and passes session-generated steps into that executor, creating a high install/execution-trust risk disproportionate to the limited provenance evidence provided.

Confidence: 81%Severity: 78%
Audit Metadata
Analyzed At
Mar 21, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fwork-mvp%2F@10153c19a5b4dd64fcb5acff4061c6a5a267f4dd
Security Audit — socket — work-mvp